Skip to main content

Vendor/product archive

openstack / cinder CVEs

Beta · best-effort

9 CVEs tagged to openstack / cinder0 Critical, 2 High, 4 Medium, 3 Low, 0 Unrated.

CVE-2017-15139

Published Aug 27, 2018

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3641

Published Oct 8, 2014

The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4183

Published Sep 16, 2013

The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users t…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4202

Published Sep 16, 2013

The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1